
Splunk Cloud Administrator
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Assist with IT and cybersecurity functions for the CDC.
• Design, implement, and oversee Splunk Enterprise environments across on-premises, MSP, and cloud infrastructures.
• Facilitate enterprise security monitoring, data integration, automation, and compliance initiatives for the CDC’s Cybersecurity Program Office.
• Develop and enhance advanced SPL queries for monitoring, reporting, and troubleshooting purposes.
• Manage data ingestion, indexing, and forwarding from cloud, server, application, and endpoint sources.
• Configure and maintain Splunk forwarders via Splunk deployment servers utilizing Syslog-NG, Cribl, AWS Lambda, and Azure Function Apps.
• Create dashboards, visualizations, reports, and alerts tailored for both technical and business users.
• Automate operational tasks and data processes using Python, Bash, and PowerShell.
• Provide support for self-hosted Splunk environments and Splunk GovCloud deployments.
• Integrate Splunk with Archer, ServiceNow, Azure, and AWS platforms.
• Diagnose and resolve platform infrastructure, networking, and security challenges that impact data visibility and performance.
• Implement and troubleshoot role-based access controls with SAML in Splunk.
• Develop, validate, and deploy custom applications to on-premises and Splunk Cloud instances.
• Utilize the Splunk AI Toolkit for tasks such as anomaly detection, forecasting, clustering, and predictive analytics.
• Contribute to monitoring and visibility for AI application stacks, including LLMs and associated infrastructure.
• Proficient in Splunk Cloud/Enterprise administration for large-scale environments.
• Strong skills in SPL, Splunk architecture, CLI management (Linux and Windows), API, ETL, AWS, and Azure.
• Familiarity with cybersecurity tools, databases, FISMA, vulnerability management, Zero Trust, CDM, and GRC platforms.
• Experience with ServiceNow, Archer, and Jira.
• Excellent communication, documentation, analytical, and teamwork skills.
• Must hold a Splunk Cloud Certified Admin designation.
• Capability to obtain and maintain a Public Trust clearance.
• Experience in the federal or healthcare sector is preferred.
• Experience with CDC/HHS is a plus.
• Knowledge of NIST guidelines is desirable.
• Experience as a Splunk Enterprise Security (ES) Admin is a plus.
• Experience as a Splunk ITSI Admin is a plus.
• Familiarity with Cribl is a plus.
• CISSP certification is a plus.
• Security+ certification is a plus.
• Familiarity with Armis is a plus.
• Must be eligible for employment in the United States.
• Gunnison is currently unable to sponsor candidates.
• 3 weeks of Personal Leave in your first year.
• 11 paid Holidays annually.
• 5 days of Flexible Time Off each year for approved training or certifications (self-study is not eligible).
• 401(k) company match at 50% up to 10% of your salary.
• Comprehensive Medical, Dental, and Vision Insurance.
• Life and Disability Insurance coverage.
• Public Transportation Subsidies.
• Certifications and Training Allowance - Up to $5,000 per year.
• Opportunities for bonuses and profit-sharing based on company and individual performance.
BlueCross BlueShield of Tennessee
Amentum
WashU IT
Alberta Blue Cross
Get handpicked remote jobs straight to your inbox weekly.